Skip to content

Security: Rossville/exam-countdown-extension

Security

SECURITY.md

Security Policy

Supported Versions

Currently supported versions of the Exam Countdown Extension:

Version Supported
Latest
< 1.0

We recommend always using the latest version of the extension for the best security and features.

Reporting a Vulnerability

We take the security of the Exam Countdown Extension seriously. If you discover a security vulnerability, please follow these steps:

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Send an email to [support@novatra.in] with:
    • A description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact assessment
    • Any suggested fixes (if available)

What to Include

Please provide as much information as possible:

  • Type of vulnerability (e.g., XSS, data exposure, permission escalation)
  • Affected version(s)
  • Steps to reproduce
  • Proof of concept (if applicable)
  • Your contact information for follow-up

Response Timeline

  • Initial Response: Within 48 hours of report
  • Status Update: Within 7 days with assessment
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-14 days
    • Medium: 14-30 days
    • Low: 30-90 days

Security Best Practices for Users

When using this extension:

  1. Download from Official Sources: Only install from Chrome Web Store, Mozilla AMO or official repository releases
  2. Keep Updated: Enable automatic updates or regularly check for new versions
  3. Review Permissions: Check what permissions the extension requests
  4. Report Suspicious Behavior: Contact us if you notice unusual activity
  5. Backup Your Data: Export your exam data regularly

Disclosure Policy

  • We follow responsible disclosure practices
  • Security researchers will be credited (with permission) after fixes are released
  • We aim to fix vulnerabilities before public disclosure
  • Security advisories will be published for significant issues

Scope

Security issues we accept:

  • ✅ Cross-Site Scripting (XSS)
  • ✅ Data leakage or unauthorized access
  • ✅ Privilege escalation
  • ✅ Security misconfigurations
  • ✅ Injection vulnerabilities

Out of scope:

  • ❌ Browser-level vulnerabilities
  • ❌ Social engineering attacks
  • ❌ Issues in third-party dependencies (report to them directly)
  • ❌ Denial of service attacks

Security Updates

Security patches will be released as:

  • Patch version updates (e.g., 1.0.x) for minor fixes
  • Minor version updates (e.g., 1.x.0) for moderate issues
  • Major version updates (e.g., x.0.0) for significant changes

Contact

For security concerns, please contact:

Thank you for helping keep the Exam Countdown Extension secure!

There aren’t any published security advisories